haussli / draft-dahm-opsawg-tacacs-security

IETF draft for new tacacs+ security features
1 stars 1 forks source link

sftp ssh subsystem #29

Closed haussli closed 3 years ago

haussli commented 3 years ago

I had added text about the sftp subsystem, whose subsystem name has not been registered with IANA, since the draft was abandoned in 2007.

Thorsten warns that trying to document anomalies is impossible. Can we be sure that this is the only one?

I would say, no. It is the only one that I know of which is widely used.

Thorsten also warns that it is likely not worth the effort to register it.

So, embracing the wisdom of Thorsten and realizing that the draft explicitly states that unregistered but syntactically correct names MUST NOT generate an error. That allows the most likely name, 'sftp', to be passed. Maybe we need do nothing further and should just remove that text about sftp altogether?

td-tacacs commented 3 years ago

Thanks for the summary John.

I would be ok with removing the text, but happy to leave it to you and Douglas to make the final decision.

dcmgashcisco commented 3 years ago

+1

haussli commented 3 years ago

Removed comment about the sftp ssh subsystem. Committed in 3c6757b9bd.